Skip to navigation
   
Asavin Wattanajantra's Blog

Ho Ho ho! Hackers prefer to work at Christmas

By Asavin Wattanajantra in Editorial

Posted in Defcon, hackers, Christmas on August 25, 2009 at 3:53 pm

Permalink | Author Profile

According to the hacker community, you’re more likely to be targeted at Christmas and New Year than at any other time.

At the annual hacker conference Defcon 17 in Las Vegas, most of the 79 hackers surveyed said they would be more active during the winter holidays, with a little more than half saying than Christmas was the best time to engage in corporate hacking.

In a survey of 79 - which really isn’t very many people for a proper survey - but I guess it makes common sense. According to the company that published the survey, it was ‘received knowledge’ that the Christmas and New Year seasons were popular with western hackers.

Chief security architect Michael Hamelin of Tufin Technologies (which carried out the survey) said: “Hackers know this is when people relax and let their hair down, and many organisations run on a skeleton staff over the holiday period.”

12345
Not yet rated
Loading ... Loading ...

 

What to do if your website gets hacked

By Asavin Wattanajantra in Editorial

Posted in SQL injection, website, hackers, hacking on August 21, 2009 at 1:32 pm

Permalink | Author Profile

SQL injections have been a big focus of mine this week - previously I blogged about how the theft of 130 million debit and credit cards were alleged to have been carried out using SQL injection techniques, and I followed it up with some reasons how it became large-scale.

Perhaps because of this media attention, HP has released some advice about what to do if Google detects that your website is hosting malware.

It says: “A frightening trend with SQL injection attacks concerns how an attacker will insert links to javascript content used to serve malicious links that may automatically compromise the users of this website.

“When this happens, Google will automatically detect this and actively deter users from  visiting your website.”

HP has published some basic recovery steps that may ensure that all content that was modified by attacker has been removed.

  1. Disconnect from the internet
  2. Backup he entire site and backend database.
  3. Save all logs and analyse them.
  4. Change all authentication - the attacker is likely to have stolen the credentials needed for website access.
  5. Reinstall OS (this is more of a precaution).
  6. Restore previous backups.
  7. Perform simple code audits.
  8. Turn the site back on.

More information can be found here.
It does have a disclaimer that this isn’t legal advice and if monetary problems occur, consider hiring a consultant and notifying the proper authorities.

12345
Not yet rated
Loading ... Loading ...

 

130 million card numbers were stolen by SQL injection

By Asavin Wattanajantra in Editorial

Posted in hackers, fraud on August 18, 2009 at 2:56 pm

Permalink | Author Profile

We’ve already covered the ‘largest identity hack’ case in some depth, but here are a few more details of the hack that comes from the press release issued by the Department of Justice (DOJ).

According to the information given, the conspirators used a ‘SQL injection technique’, which it said “seeks to exploit computer networks by finding a way around the network’s firewall to steal credit card information”.

We’ve covered a number of stories about SQL injections before, but never anything on this kind of scale financially. It’ll be interesting to see what other details emerge about the technical aspects of the attack.

12345
Not yet rated
Loading ... Loading ...

 

Hiring hackers for national security? You’re havin’ a laff!

By Asavin Wattanajantra in Editorial

Posted in national security, hackers, hacking, government, Security on June 26, 2009 at 3:14 pm

Permalink | Author Profile

I wasn’t there to see the first statements of the new Cyber Security minister Lord West, but according to reports he admitted that the government has hired a team of former “naughty boy hackers” for its new Cyber Security Operations Centre.

The BBC quotes him as saying: “You need youngsters who are deep into this stuff… If they have been slightly naughty boys, very often they really enjoy stopping other naughty boys.”

OK -  first up these are fine words for a Cyber Security Minister. Naughty boys? - I’ve only been writing on security for the last year and a half, but I already realise that many of the criminals he’s talking about aren’t ‘naughty boys’ - they are hardened criminals fully intent on making as much profit as possible.

I get the feeling he’s one of those people who don’t think that cyber criminals are ‘real’ criminals because they play on the computer. And this is somebody the government has employed to oversee its cyber security. Great.

And he’s employed hackers with criminal records? This is all well and good in a movie, but as security expert Rik Ferguson notes, the government has actually hired a team of people who have committed criminal acts and given them jobs.

He also makes the point that if you’re going to hire hackers to stop hackers, then why employ the naughty crap ones who managed top get caught? - or ’script-kiddies’ as Ferguson puts it -  the laughing stock. Yep, Lord West - good choice!

Even if this is just misquoting or taken out of context, it’s a little worrying that the Cyber Security Minister himself seems to be so inept at understanding the real problems of IT security.  Last week I wrote a feature on what the basic qualifications a Cyber Security Minister might actually need - I don’t think Lord West ticks any of the boxes.

Maybe it was the case that none of the ministers around Gordon Brown had the technological expertise or IT training for this role. In this case they really should have simply found one. I mentioned John Suffolk, government chief information officer, as somebody who had the technology knowledge for the role.

It might be the case that Neil Thompson, the prospective new director for the Office of Cyber Security, might be the person who really will shape the cyber security of Britain. As security expert Graham Cluley said in my feature, maybe its good to have an unknown person in the role who will knock heads together and do what’s needed.

But hopefully he won’t be listening to the ‘Cyber Security Minister’ Lord West. He may be all well and good when it comes to knowledge of actual physical warfare - but cyber war is a completely different beast. Hope you know what you’re doing Gordon.

12345
Not yet rated
Loading ... Loading ...

 

   
Tag cloud

traffic Sega Cisco update Transformers Amazon World of Warcraft pod casting Daily Mail funny teenagers science Spotify status filters staff swear words Second Life Digg FBI mobile old school offline military Nintendo death flashmob ID cards IT PRO ENISA privacy hacking morph Friendfeed sony playstation Nintendo Sega Sinclair Spectrum gaming Mario Sonic Flurry legal iPhone lapto Pirate Bay crime map Google Facebook remote working software spam top ten tips fun hype Digital Britain Fraud Mozilla Steve Jobs Twitter medials flaw murder sightings PR poking Google Street View Scrabble BERTI SQL injection control robots Beijing worm IM James Bond rickrolling cyber crime RSS Twitpocalypse nokia trend micro instant messaging Google flexible working Apple fire social media Microsoft RPG kill cybercrime password tool unlimited surveillance MMORPG brainwaves Mario video video games streaming feed journalism Lewis hamilton pride Black Hat hack hackers Hitwise multimedia illegal broadband vote downloading alibi growth Star Trek Mafia Wars government human clones Sophos Kaminsky bendy BlackBerry future browser Wherecloud internet malware Republicans virtual worlds ASA Bill Gates paranoia Dark Market eBooks Terminator NHS music ducks replies uSwitch YouTube tech brain phishing Clampi alcohol Firefox university of portsmouth Google Reader Klingon hatred David Blunkett data breaches satnav credit card data app DNSSEC Christmas phone DNS Olympics Sonic Google Maps Kindle website news pirate research smartphone Farmville opinion crime
Advertisement
Advertisement